GHSA-8wvg-r2j4-3737Medium▾ SunlitVikunja: Assignee email addresses disclosed to read-only project members via the task assignees endpoint
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
TaskAssginee.ReadAll returns assignee user objects without blanking the Email field, disclosing assignee email addresses to any read-only project member. Every sibling path that returns user objects obfuscates the email; this one does not.
pkg/models/task_assignees.go (~lines 306-344) does Select("users.*") and returns the result directly. User.Email is json:"email,omitempty", so a non-empty value always serializes. The endpoint gates on task.CanRead, so a read-only member passes. Sibling paths blank the field: pkg/models/tasks.go:530, pkg/models/project_users.go:216, pkg/models/teams.go:177, pkg/models/label_task.go:312, pkg/models/task_attachment.go:511. The omission here reads as an oversight, not a decision.
The same file's getRawTaskAssigneesForTasks (~line 56) also selects users.* but is safe because its only caller (addAssigneesToTasks) blanks the email afterwards.
GET /api/v1/tasks/{id}/assignees (reader with permission:0)
-> [{"id":37,"username":"...","email":"[email protected]", ...}]
Same leak on GET /api/v2/tasks/{id}/assignees (routes through the identical model method). Contrast: GET /api/v1/projects/{id}/projectusers and the project task-embed both return the same users with no email.
Disclosure of assignees' email addresses to users who should only see usernames. Read-only.
Blank Email on each returned user in TaskAssginee.ReadAll before returning, matching the sibling paths. Covers v1 and v2 at once.
code.vikunja.io/api <= 2.5.0Upgrade to a patched release:
code.vikunja.io/api 2.6.0Connected by shared product, vendor, weakness, or advisory.
GHSA-3hc7-r24j-rpwcMediumVikunja: Cross-project task disclosure through subtask expansion
GHSA-g38j-7v97-x298MediumVikunja: CalDAV relation creation bypasses TaskRelation.CanCreate, allowing an unauthorized write into any task by known UID
GHSA-w2ch-4xgr-22wwLowVikunja: Task relation deletion does not check read access to the other task, allowing cross-project relation removal
GHSA-37rx-7pj5-p885High· 7.5Duplicate Advisory: Vikunja: Read-only project members can obtain any link share's access hash via the single-share read endpoint (v1 and v2) and escalate to the share's permission level
GHSA-2922-qgfj-pr7vMedium· 4.3Duplicate Advisory: Vikunja: Any user can enumerate every team and its members by attaching arbitrary teams to a throwaway project
GHSA-vcgv-7rvm-m3vpMedium· 4.3Duplicate Advisory: Vikunja: Link-share token can enumerate users through the v2 API